BSCBLOCK
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
📦 BNBChain MCP – Binance Smart Chain Tool Server (MCP + CLI Ready)
A comprehensive blockchain tool server for BNB, BEP-20 tokens, smart contract deployment and interaction built on BNB Smart Chain (BSC) and compatible with other EVM networks.
Technology Stack
- Blockchain: BNB Smart Chain (BSC)
- Web3 Libraries: Viem 2.23.11, PancakeSwap SDK 5.8.8
- CLI/Backend: TypeScript, Node.js (ESM)
- Protocol: Model Context Protocol (MCP) SDK 1.4.0
- Security: AES encryption with bcrypt for private key protection
- Token Security: GoPlus SDK for security checks
- Data Provider: Moralis SDK 2.27.2 for blockchain data
Supported Networks
- BNB Smart Chain Mainnet (Chain ID: 56)
- RPC: https://bsc-dataseed.binance.org (default)
- Custom RPC supported via environment configuration
Contract Addresses
Features
- Low-cost BNB & BEP-20 transfers - Optimized for BSC's low gas fees
- PancakeSwap V2/V3 integration - Automated swaps, liquidity management, and position tracking
- Four.Meme platform support - Create, buy, and sell meme tokens directly
- Security-first architecture - AES-256 encrypted private keys with bcrypt password protection
- Token security analysis - Built-in GoPlus security checks for token verification
- Gas-efficient operations - Smart routing for optimal gas usage on BSC
- AI-ready MCP protocol - Seamless integr
2bd1300f1ee3OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add bnbchain-mcp --env BSC_WALLET_PRIVATE_KEY=${BSC_WALLET_PRIVATE_KEY} -- npx -y [email protected]{
"mcpServers": {
"bnbchain-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"BSC_WALLET_PRIVATE_KEY": "${BSC_WALLET_PRIVATE_KEY}"
}
}
}
}Exposed tools (11)
7 read · 3 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Add_PancakeSwap_Liquidity | write | 💧Provide liquidity to PancakeSwap trading pairs |
Buy_Meme_Token | read | 🚀Purchase meme tokens on BNBChain |
Get_Wallet_Info | read | 👛View detailed balance and holdings for any wallet address |
PancakeSwap_Token_Exchange | read | 💱Exchange tokens on BNBChain using PancakeSwap DEX |
QueryMemeTokenDetails | read | Fetches token details for a given meme token using the four.meme API. Default price in USDT. |
Remove_PancakeSwap_Liquidity | destructive | 🔄Withdraw your liquidity from PancakeSwap pools |
Sell_Meme_Token | read | 💰Sell meme tokens for other currencies |
Send_BEP20_Token | write | 📤Send any BEP-20 token to another wallet (requires wallet check first) |
Send_BNB | write | 💎Transfer native token (BNB), Before execution, check the wallet information first |
Token_Security_Check | read | 🔒Analyze BNBChain tokens for potential security risks powered by GoPlus |
View_PancakeSwap_Positions | read | 📊View your active liquidity positions on PancakeSwap |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (4 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
exec(`osascript -e '${appleScript}'`, (error, stdout, stderr) => {exec(`powershell -ExecutionPolicy Bypass -File "${tempScriptPath}"`, (error, stdout, stderr) => {Remove_PancakeSwap_Liquidity
const pkgPath = path.resolve(__dirname, '../../package.json');
@goplus/sdk-node, @modelcontextprotocol/sdk, @pancakeswap/sdk, @pancakeswap/tokens, @pancakeswap/v3-sdk, bcrypt, chalk, dotenv
> A plug-and-play MCP tool server to **send BNB**, **transfer BEP-20 tokens**, **deploy tokens**, and **interact with smart contracts** on the **Binance Smart Chain (BSC)** — built for **Claude Deskto
sources/BUSD_TRANSFER_MCP.mp4
Gates applied: no_behavioural_pass, no_license.
2bd1300f1ee3full audit observations/trust-audit/mcp-server/termix-official__bsc.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 2bd1300f1ee3 | BLOCK | D | 69 | first audit |
Questions
What tools does BSC expose?
11 in total: 7 read-only, 3 that write, and 1 that can delete or overwrite (Remove_PancakeSwap_Liquidity). Every one is listed on this page with its risk.
Is BSC safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does BSC need?
It reads BSC_WALLET_PRIVATE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does BSC run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as bnbchain-mcp at 1.0.12.
How current is this page?
The grade is for one exact copy of the source (2bd1300f1ee3), read on 2026-10-07. The repository is watched and re-audited when it changes.